Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 16 articles for you...
83

Targeted Fragmentation: Covert Channels Using Hard Drives

A team of researchers has presented a steganographic technique which can be used to conceal data on a hard drive. The technique is essentially based on targeted fragmentation of clusters when saving a file in the FAT file system. . When decoded, the distance between clusters reveals the binary sequence of the hidden data. Two (numerically) sequential clusters, for example, mean that the following bit is equal to the previous one. If the distance to the next cluster is greater, this means that the next bit is not equal to the previous bit. In this way, a series of clusters making up a saved file yields a defined bit stream. If the reader knows the state of the starting bit, he is able to obtain the correct bit stream. The link for this article located at H Security is no longer available. . When decoded, the distance between clusters reveals the binary sequence of the hidden data. Two (num. researchers, presented, steganographic, technique, which, conceal. . LinuxSecurity.com Team

Calendar%202 Apr 26, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

FBI Arrests 11 Russian Spies Using Steganography for Secret Messaging

In a case that smacks of a Cold War spy novel, the FBI has arrested 11 suspected Russian spies who for years had blended into day-to-day American life in the suburbs and cities. Aside from hiding their true identities and posing as legitimate American citizens, the suspects also masked their communications with their intelligence agency back home in Moscow, using an oft-forgotten form of stealth communication -- steganography.. According to U.S. Department of Justice legal filings, the defendants used a steganography tool, one that is not available commercially, to conceal their electronic communiques with Russian officials in the so-called SVR, a Russian Federation foreign intelligence body. Steganography hides text or images within image files or other innocuous-looking files. The alleged spies used steganography to hide messages within digital images on websites: "The software package permits the SVR clandestinely to insert encrypted data into images that are located on publicly-available websites without the data being visible," according to one of the DoJ's legal filings. "The encrypted data can be removed from the image, and then decrypted, using SVR-provided software. Similarly, SVR-provided software can be used to encrypt data, and then clandestinely to embed the data in images on publicly-available websites." FBI agents discovered the steganography software during their forensics investigations of computer disks they recovered in the Boston, Seattle, and New Jersey residences where some of the suspects lived, according to the legal filings (PDF), which detail how the suspects assimilated themselves in the U.S. in order to glean U.S. secrets, including nuclear weapons research, for Moscow. The link for this article located at Dark Reading is no longer available. . Recent court documents reveal that agents from Russia have utilized advanced cryptographic techniques to hide their messages, effectively dodging surveillance.. Steganography, Covert Communication, Foreign Intelligence, ElectronicEspionage. . LinuxSecurity.com Team

Calendar%202 Jun 30, 2010 User Avatar LinuxSecurity.com Team Cryptography
67

Exploring Steganography Methods for Data Hiding in Rainbow Tables

Steganography is the art of hiding messages so that uninitiated wouldn't suspect the presence of a message. A rainbow table is a huge binary file used for password cracking. This is the first in a series of posts on research I've done on how to hide data in rainbow tables, and how to detect its presence. There are several steganography algorithms to hide data in pictures. They often involve changing the least-significant-bits of the numbers representing the color or another visual property of a pixel. This minute difference cannot be perceived by the naked eye, but it this there. The size of the data you can hide in a picture is limited by the size of the picture and by the numbers of bits involved in the steganography algorithm. It. The link for this article located at DiderStevens is no longer available. . Dive into the intriguing realms of steganography along with advanced methods of data concealment employing rainbow tables in this enlightening piece.. Steganography Techniques, Data Hiding Algorithms, Rainbow Table Security. . LinuxSecurity.com Team

Calendar%202 May 02, 2007 User Avatar LinuxSecurity.com Team Cryptography
67

Discover Steganography Tools For Hidden Data Protection

Remember those invisible ink kits from when you were a kid? You'd write a secret message that no one could see unless they had a black light or the decoder marker. The digital equivalent of invisible ink is steganography software, apps that embed files and data inside other files, hidden from everyone who doesn't know any better. You don't have to be a trained spy plotting international espionage to put steganography to good use. With some free tools for both the Mac and PC, you can embed secret information in image, PDF, HTML and MP3 files for fun or profit. . Unlike encryption, which obscures data in such a way that it's obvious someone's keeping something from listeners-in (and therefore heightens interest in that info), stego techniques offer no hint to the outsider that there's any private data contained within the visible file. Like hiding your valuables from burglars in an empty cereal box in your kitchen cabinet, steganography keeps the existence of the secret item from everyone but those in the know. The link for this article located at Life Hacker is no longer available. . Investigate software solutions for steganography that conceal information within various file types, promoting digital safety and maintaining a low profile.. Steganography tools, Data hiding techniques, Digital privacy software, File manipulation methods. . LinuxSecurity.com Team

Calendar%202 Jan 26, 2007 User Avatar LinuxSecurity.com Team Cryptography
81

Impact of Steganography on Cyber Terrorism Communication Tools

Following my previous post on Cyber Terrorism Communications and Propaganda, I'm continuing to summarize interesting findings on the topic. The use of encryption to ensure the confidentiality of a communication, be it criminals or terrorists taking advantage of the speed and cheap nature of Internet communications, is often taken as the de-facto type of communication. I feel that it's steganographic communication in all of its variety that's playing a crucial role in terrorist communications. It's never been about the lack of publicly or even commercially obtainable steganographic tools, but the ability to know where and what to look for. Here's a brief comment on a rather hard to intercept communication tool - SSSS - Shamir's Secret Sharing Scheme : . "No other medium can provide better speed, connectivity, and most importantly anonymity, given it The link for this article located at Dancho Danchev is no longer available. . 'No other medium can provide better speed, connectivity, and most importantly anonymity, given itThe. previous, cyber, terrorism, communications, propaganda, continuing, summa. . LinuxSecurity.com Team

Calendar%202 Aug 31, 2006 User Avatar LinuxSecurity.com Team Privacy
67

Investigation of USENET Images for Steganography Detection Techniques

After scanning two million images from eBay without finding any hidden messages, we extended the scope of our analysis. A detailed description of the detection framework can be found in Detecting Steganographic Content on the Internet. This page provides details about the analysis of one million images from the Internet Archive's USENET archive. Processing the one million images with stegdetect results in about 20,000 suspicious images. We launched a dictionary attack on the JSteg and JPHide positive images. The dictionary has a size of 1,800,000 words and phrases. The disconcert cluster used to distribute the dictionary attack has a peak performance of roughly 87 GFLOPS. . . After scanning two million images from eBay without finding any hidden messages, we extended the sco. scanning, million, images, without, finding, hidden, messages, extended. . LinuxSecurity.com Team

Calendar%202 Jul 10, 2006 User Avatar LinuxSecurity.com Team Cryptography
67

Exploring Steganography Risks in Information Technology Security

Steganography is a subject which is rarely touched upon by most IT Security Enthusiasts. Most people don't see Steganography has a potential threat, some people don't even know what Steganography is. With this FAQ I hope to answer any questions anyone may want to ask about Steganography, and to educate people so they can understand what exactly Steganography is. Is Steganography a potential threat? Well your about to find out. . The link for this article located at InfoSecWriters is no longer available. . The link for this article located at InfoSecWriters is no longer available. . steganography, subject, which, rarely, touched, security, enthusiasts, people. . LinuxSecurity.com Team

Calendar%202 Mar 29, 2006 User Avatar LinuxSecurity.com Team Cryptography
83

Phishing Attacks: Steganography Threatens Corporate Security

In the escalating clash between online scammers and security vendors, the attackers have once again developed new tactics that give them the upper hand in bypassing filters and infiltrating corporate networks, experts say. . . .. The new techniques, which experts began seeing sporadically earlier this year and in large waves in recent weeks, involve the use of a process called steganography, or embedding or hiding text in an image. In the most recent cases, spam and phishing messages have incorporated complex images containing text. In some cases, the image files include hidden code designed to exploit known vulnerabilities in e-mail clients and Web browsers. The most prominent example of the steganography wave is a recent variation on the ubiquitous Citibank phishing scam that attempts to lure recipients into disclosing online banking user names and passwords. Previous versions used text and images, such as authentic-looking Citibank logos and privacy seals. But versions that began surfacing recently are made up of one large image file containing all the text. "We continually modify our systems to enhance safeguards for our customers," said a spokesperson for Citibank, a unit of Citigroup Inc., in New York. "It is also important that consumers be aware of these issues and act appropriately." The link for this article located at Dennis Fisher is no longer available. . The new techniques, which experts began seeing sporadically earlier this year and in large waves in . escalating, clash, between, online, scammers, security, vendors, attackers, again. . LinuxSecurity.com Team

Calendar%202 Sep 13, 2004 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200